You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.

Register a free account to unlock additional features at BleepingComputer.com

Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

While researching something I walked into an ambush. I started with Google and followed one link to another without paying particular attention to the web site addresses unless the information was useful.

Then I clicked onto a site with only 1 posting. I instantly knew I was in trouble but it was too late. I X'ed out the program and found my desktop picture replaced by a black background with a full screen message saying my computer was infected and to "Click Here" to get rid of the infection.

Instead I went to Safe Mode and ran Anti-Virus and Anti-Spyware software until they all said my computer was clean. (Honesty in advertising: the laptop's RAM is maxed out at 128M. Running A-V and A-S in memory makes it so slow it is truly unusable.)

Now when the computer boots up I get my Desktop picture at first, but after the icons start appearing on the screen the entire screen changes to a blue color and then the entire screen changes again to a white color while the text below each icon still has the blue background.

This blue color can be changed in Control Panel / Display / Appearance / Color scheme as can the Desktop picture in C-P / D / Desktop.

When I <right-click> on the screen, instead of Control Panel stuff, I go to Properties with only the General tab and

Address: file://C:WINDOWS\Web\desktop.html(URL)

So can anyone please tell me how to get rid of this junk ?

Here is the Hijack log. Thanks

P.S. The laptop's hard-drive is only 4G. The update to SP2 wants almost 2G for the archive and so won't do the update. I don't want to have to uninstall half the computer to do the update. Any ideas ?

desktop picture replaced by a black background with a full screen message saying my computer was infected and to "Click Here" to get rid of the infection.

Note anything specific here that may help determine what infection this is.

Let's see if we can get the desktop issue addressed first.

Download smitfraud.reg to your desktop.- Double click the smitfraud.reg icon on your desktop.- When it asks if you want to add the data to the registry, say Yes.

Go to the Control Panel and do the following:

- Click on the Display item.- Click on the Desktop tab.- Click on the Customize Desktop button.- Click on the Web tab.- In the Web Pages area:--- Remove the checkmark from each item in the box.--- Click on each item in turn and click the Delete button.- Click the Ok button.- Make any changes to your Desktop, Background and Themes that you want and then close the Display dialog.

Can you configure your desktop now?

Please post a fresh HJT log along with any further description you have of the 'infected' screen.

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.